作者
Alexander Adamov, Vladimir Hahanov, Anders Carlsson
发表日期
2014/9/26
研讨会论文
Proceedings of IEEE East-West Design & Test Symposium (EWDTS 2014)
页码范围
1-5
出版商
IEEE
简介
Botnets became the powerful cyber weapon that involves tens of millions of infected computers - “cyber zombies” - all over the world. The security industry makes efforts to prevent spreading botnets and compromising an Individual Cyberspace (IC)[1] of users in such way. However, botnets continue existing despite numerous takedowns initiated by antivirus companies, Microsoft, FBI, Europol and others. In this paper we investigate existed methods of traffic detection represented mostly by IDS system and discover new indicators that can be utilized for improving botnet traffic detection. To do this we analyse the most prevalent backdoors communication protocols that stay behind of the popular botnets. As a result, we extracted new data that might be used in detection routines of IDS (Intrusion Detection System). An objective of the study is mining new indicators of compromise from botnet traffic and using them to …
引用总数
201520162017201820192211
学术搜索中的文章
A Adamov, V Hahanov, A Carlsson - Proceedings of IEEE East-West Design & Test …, 2014